---
id: CVE-2025-49796
title: A vulnerability was found in libxml2
summary: >-
  A vulnerability was found in libxml2. Processing certain sch:name elements
  from the input XML file can trigger a memory corruption issue. This flaw
  allows an attacker to craft a malicious XML input file that can lead libxml to
  crash, res…
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H'
cwe:
  - CWE-125
vendor: Red Hat
product: libxml2
affected:
  - libxml2 < 2.15.0
  - libxml2 (all versions)
  - libxml2 (all versions)
  - libxml2 (all versions)
  - libxml2 (all versions)
  - libxml2 (all versions)
  - libxml2 (all versions)
  - libxml2 (all versions)
  - libxml2 (all versions)
  - libxml2 (all versions)
  - libxml2 (all versions)
  - libxml2 (all versions)
  - libxml2 (all versions)
  - libxml2 (all versions)
  - libxml2 (all versions)
  - libxml2 (all versions)
  - libxml2 (all versions)
  - libxml2 (all versions)
  - libxml2
  - rhcos (all versions)
  - rhcos (all versions)
  - rhcos (all versions)
  - rhcos (all versions)
  - rhcos (all versions)
  - rhcos (all versions)
  - rhcos (all versions)
  - rhcos (all versions)
  - web-terminal/web-terminal-rhel9-operator (all versions)
  - web-terminal/web-terminal-tooling-rhel9 (all versions)
  - web-terminal/web-terminal-tooling-rhel9 (all versions)
  - openshift-serverless-1/logic-data-index-ephemeral-rhel8 (all versions)
  - openshift-serverless-1/logic-data-index-postgresql-rhel8 (all versions)
  - openshift-serverless-1/logic-db-migrator-tool-rhel8 (all versions)
  - openshift-serverless-1/logic-jobs-service-ephemeral-rhel8 (all versions)
  - openshift-serverless-1/logic-jobs-service-postgresql-rhel8 (all versions)
  - openshift-serverless-1/logic-kn-workflow-cli-artifacts-rhel8 (all versions)
  - openshift-serverless-1/logic-management-console-rhel8 (all versions)
  - openshift-serverless-1/logic-operator-bundle (all versions)
  - openshift-serverless-1/logic-rhel8-operator (all versions)
  - openshift-serverless-1/logic-swf-builder-rhel8 (all versions)
  - openshift-serverless-1/logic-swf-devmode-rhel8 (all versions)
  - cert-manager/jetstack-cert-manager-rhel9 (all versions)
  - compliance/openshift-file-integrity-rhel8-operator (all versions)
  - discovery/discovery-server-rhel9 (all versions)
  - libxml2-main (all versions)
  - insights-proxy/insights-proxy-container-rhel9 (all versions)
  - libxml2
  - openshift/ose-rhel-coreos-8 (all versions)
patched:
  - enterprise_linux_server_v_7_els
  - enterprise_linux_server_optional_v_7_els
  - openshift_container_platform 4.12
  - 8base_openshift_serverless_1_36
  - openshift_container_platform 4.13
  - openshift_container_platform 4.14
  - openshift_container_platform 4.16
  - openshift_container_platform 4.17
  - openshift_container_platform 4.18
  - openshift_container_platform 4.19
  - openshift_container_platform 4.20
  - web_terminal_1_11_on_rhel 9
  - web_terminal_1_12_on_rhel 9
  - enterprise_linux_appstream_v_10
  - enterprise_linux_appstream_v_8
  - enterprise_linux_appstream_aus_v_8_2
  - enterprise_linux_appstream_aus_v_8_4
  - enterprise_linux_appstream_eus_extension_v_8_4
  - enterprise_linux_appstream_aus_v_8_6
  - enterprise_linux_appstream_e4s_v_8_6
  - enterprise_linux_appstream_tus_v_8_6
  - enterprise_linux_appstream_e4s_v_8_8
  - enterprise_linux_appstream_tus_v_8_8
  - enterprise_linux_appstream_e4s_v_9_0
  - enterprise_linux_appstream_e4s_v_9_2
  - enterprise_linux_appstream_eus_v_9_4
  - enterprise_linux_appstream_v_9
  - enterprise_linux_baseos_v_10
  - enterprise_linux_baseos_v_8
  - enterprise_linux_baseos_aus_v_8_2
  - enterprise_linux_baseos_aus_v_8_4
  - enterprise_linux_baseos_eus_extension_v_8_4
  - enterprise_linux_baseos_aus_v_8_6
  - enterprise_linux_baseos_e4s_v_8_6
  - enterprise_linux_baseos_tus_v_8_6
  - enterprise_linux_baseos_e4s_v_8_8
  - enterprise_linux_baseos_tus_v_8_8
  - enterprise_linux_baseos_e4s_v_9_0
  - enterprise_linux_baseos_e4s_v_9_2
  - enterprise_linux_baseos_eus_v_9_4
published: '2025-06-16'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T18:17:03.760'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-49796'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2025:10630'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:10698'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:10699'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:11580'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:12098'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:12099'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:12199'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:12237'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:12239'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:12240'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:12241'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:13267'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:13335'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:15397'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:15827'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:15828'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:18217'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:18218'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:18219'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:18240'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:19020'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:19041'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:19046'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:19894'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:21913'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:0934'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:62549'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:7519'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2025-49796'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2372385'
    label: secalert@redhat.com
  - url: 'https://gitlab.gnome.org/GNOME/libxml2/-/issues/933'
    label: secalert@redhat.com
  - url: 'https://lists.debian.org/debian-lts-announce/2025/07/msg00014.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://cert-portal.siemens.com/productcert/html/ssa-253495.html'
    label: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
  - url: 'https://cert-portal.siemens.com/productcert/html/ssa-577017.html'
    label: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-49796.json
  - url: 'https://www.cve.org/CVERecord?id=CVE-2025-49796'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2025-49796'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
epss: 0.01558
epssPercentile: 0.73682
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2025-06-16T15:32:55.790163Z'
ingestedAt: '2026-06-29T13:24:34.370Z'
---

## Overview

A vulnerability was found in libxml2. Processing certain sch:name elements from the input XML file can trigger a memory corruption issue. This flaw allows an attacker to craft a malicious XML input file that can lead libxml to crash, resulting in a denial of service or other possible undefined behavior due to sensitive data being corrupted in memory.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **RHSA-2025:12240** · Red Hat · fixed in: Red Hat Enterprise Linux Server (v. 7 ELS), Red Hat Enterprise Linux Server Optional (v. 7 ELS) · released 2025-07-30 · [advisory](https://access.redhat.com/errata/RHSA-2025:12240)
- **RHSA-2025:19894** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.12 · released 2025-11-13 · [advisory](https://access.redhat.com/errata/RHSA-2025:19894)
- **RHSA-2026:0934** · Red Hat · fixed in: 8Base-Openshift-Serverless-1.36 · released 2026-01-22 · [advisory](https://access.redhat.com/errata/RHSA-2026:0934)
- **RHSA-2025:18240** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.13 · released 2025-10-23 · [advisory](https://access.redhat.com/errata/RHSA-2025:18240)
- **RHSA-2025:19041** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.14 · released 2025-10-30 · [advisory](https://access.redhat.com/errata/RHSA-2025:19041)
- **RHSA-2026:62549** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.16 · released 2026-09-10 · [advisory](https://access.redhat.com/errata/RHSA-2026:62549)
- **RHSA-2025:18218** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.17 · released 2025-10-22 · [advisory](https://access.redhat.com/errata/RHSA-2025:18218)
- **RHSA-2025:19046** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.18 · released 2025-10-29 · [advisory](https://access.redhat.com/errata/RHSA-2025:19046)
- **RHSA-2025:18217** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.19 · released 2025-10-22 · [advisory](https://access.redhat.com/errata/RHSA-2025:18217)
- **RHSA-2025:15397** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.20 · released 2025-10-21 · [advisory](https://access.redhat.com/errata/RHSA-2025:15397)
- **RHSA-2025:15828** · Red Hat · fixed in: Red Hat Web Terminal 1.11 on RHEL 9 · released 2025-09-15 · [advisory](https://access.redhat.com/errata/RHSA-2025:15828)
- **Red Hat VEX** · Important · affected: Red Hat Enterprise Linux 6, Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat Enterprise Linux 6, Red Hat OpenShift Container Platform 4 · updated 2026-09-18 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-49796.json)
